{"id":167905,"date":"2026-04-08T11:11:59","date_gmt":"2026-04-08T09:11:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya"},"modified":"2026-04-08T11:11:59","modified_gmt":"2026-04-08T09:11:59","slug":"uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya","title":{"rendered":"Dob\u00ebsia n\u00eb Flatpak, e cila lejon ekzekutimin e kodit jasht\u00eb mjedisit t\u00eb izoluar.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb nj\u00eb version korrigjues t\u00eb publikuar disa or\u00eb m\u00eb par\u00eb p\u00ebr sistemin e pakove t\u00eb autonomuara Flatpak 1.16.4, si dhe n\u00eb versionin eksperimental 1.17.4, \u00ebsht\u00eb riparuar nj\u00eb dob\u00ebsi (CVE-2026-34078) q\u00eb lejon nj\u00eb aplikacion t\u00eb d\u00ebmsh\u00ebm ose t\u00eb komprometuar n\u00eb formatin flatpak t\u00eb anashkaloj\u00eb modalitetin e vendosur t\u00eb izolimit sandbox, t\u00eb qasje n\u00eb skedar\u00ebt n\u00eb sistemin kryesor dhe t\u00eb ekzekutoj\u00eb kod t\u00eb rast\u00ebsish\u00ebm jasht\u00eb modit t\u00eb izolimit. Problem\u00ebs iu atribua nj\u00eb nivel kritik rreziku (9.3 nga 10).      <\/p>\n<p>Vulnerabiliteti \u00ebsht\u00eb i pranish\u00ebm n\u00eb sh\u00ebrbimin D-Bus flatpak-portal, i cili siguron nisjen e \"portaleve\", t\u00eb cilat p\u00ebrdoren p\u00ebr t\u00eb organizuar qasjen n\u00eb burimet e ambientit kryesor nga aplikacione t\u00eb izoluara. Problemi shkaktohet nga fakti q\u00eb sh\u00ebrbimi flatpak-portal lejon aplikacionin t\u00eb specifikoj\u00eb n\u00eb opsionin sandbox-expose rrug\u00ebt e skedar\u00ebve, t\u00eb cilat p\u00ebr shkak t\u00eb munges\u00ebs s\u00eb kontrolleve t\u00eb duhura mund t\u00eb jen\u00eb lidhje simbolike q\u00eb tregojn\u00eb n\u00eb pjes\u00eb arbitrare t\u00eb sistemit t\u00eb skedar\u00ebve.  <\/p>\n<p>Para se t\u00eb montoj\u00eb, sh\u00ebrbimi zbulohet lidhjen simbolike dhe monton n\u00eb ambientin sandbox rrug\u00ebn n\u00eb t\u00eb cil\u00ebn ajo tregon, duke lejuar k\u00ebshtu anashkalimin e izolimit dhe qasjen p\u00ebr lexim dhe shkruarje n\u00eb skedar\u00ebt e ambientit host. P\u00ebr t\u00eb organizuar ekzekutimin e kodit t\u00eb tij n\u00eb sistem, p\u00ebr shembull, mund t\u00eb shtoj\u00eb nj\u00eb skenar q\u00eb nis automatikisht, si \"~\/ .bashrc\" ose \"~\/ .profile\", ose t\u00eb modifikoj\u00eb skedarin \"~\/ .ssh\/ authorized_keys\" me \u00e7el\u00ebsat SSH.      <\/p>\n<p>Statusi i eliminimit t\u00eb vulnerabilitetit n\u00eb shp\u00ebrndarjet mund t\u00eb vler\u00ebsohet n\u00eb k\u00ebto faqe (n\u00ebse faqja nuk \u00ebsht\u00eb e aksesueshme, at\u00ebher\u00eb zhvilluesit e shp\u00ebrndarjes nuk kan\u00eb filluar akoma t\u00eb shqyrtojn\u00eb problemin): Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch, Fedora. Si nj\u00eb m\u00ebnyr\u00eb alternative p\u00ebr mbrojtje mund t\u00eb shky\u00e7ni sh\u00ebrbimin flatpak-portal: sudo systemctl --global mask flatpak-portal.service &amp;&amp; systemctl --user stop flatpak-portal.service      <\/p>\n<p>P\u00ebrve\u00e7 dob\u00ebsis\u00eb kritike, n\u00eb versionin e ri jan\u00eb zgjidhur edhe tre probleme t\u00eb tjera me sigurin\u00eb:  <\/p>\n<ul>\n<li class=\"l\"> Mund\u00ebsia (CVE-2026-34079) p\u00ebr t\u00eb fshir\u00eb nj\u00eb skedar t\u00eb rast\u00ebsish\u00ebm n\u00eb sistemin e skedar\u00ebve t\u00eb sistemit prit\u00ebs. Problemi shkaktohet nga fakti se flatpak, gjat\u00eb pastrimit t\u00eb caches s\u00eb vjet\u00ebruar ld.so, nuk kontrollon vendndodhjen aktuale t\u00eb skedarit q\u00eb po fshihet n\u00eb katalogun e caches.\n<li class=\"l\"> Mund\u00ebsia e leximit t\u00eb skedar\u00ebve t\u00eb rast\u00ebsish\u00ebm n\u00eb kontekstin e system-helper n\u00eb sistemet me depo t\u00eb konfiguruar t\u00eb imazheve OCI p\u00ebrmes manipulimeve me lidhjet simbolike.\n<li class=\"l\"> Mund\u00ebsia p\u00ebr t\u00eb intervenuar n\u00eb p\u00ebrpunimin e k\u00ebrkesave p\u00ebr ndalimin e shkarkimeve t\u00eb aplikacioneve, e cila i lejon nj\u00eb p\u00ebrdoruesi t\u00eb pengoj\u00eb nj\u00eb p\u00ebrdorues tjet\u00ebr t\u00eb ndaloj\u00eb shkarkimin.          <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65170\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u043e\u0432 \u043d\u0430\u0437\u0430\u0434 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0441\u0430\u043c\u043e\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 Flatpak 1.16.4, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430\u043b\u044c\u043d\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 1.17.4, \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-34078), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u043c\u0443 \u0438\u043b\u0438 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044e \u0432 \u0444\u043e\u0440\u043c\u0430\u0442\u0435 flatpak, \u043e\u0431\u043e\u0439\u0442\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u0440\u0435\u0436\u0438\u043c sandbox-\u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438, \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u0434 \u0432\u043d\u0435 \u0440\u0435\u0436\u0438\u043c\u0430 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (9.3 \u0438\u0437 10). [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-167905","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u043e\u0432 \u043d\u0430\u0437\u0430\u0434 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0441\u0430\u043c\u043e\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 Flatpak 1.16.4, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430\u043b\u044c\u043d\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 1.17.4, \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-34078), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u043e Flatpak, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432\u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u043e\u0432 \u043d\u0430\u0437\u0430\u0434 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0441\u0430\u043c\u043e\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 Flatpak 1.16.4, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430\u043b\u044c\u043d\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 1.17.4, \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-34078), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-08T09:11:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-08T09:11:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabiliteti n\u00eb Flatpak, i cili lejon ekzekutimin e kodit jasht\u00eb mjedisit t\u00eb izoluar | ProHoster","description":"N\u00eb publikimin e mbikorrigjuar disa or\u00eb m\u00eb par\u00eb t\u00eb sistemit t\u00eb paketave autonome Flatpak 1.16.4, si dhe n\u00eb versionin eksperimental 1.17.4, \u00ebsht\u00eb eliminuar nj\u00eb vulnerabilitet (CVE-2026-34078) q\u00eb lejon.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u043e Flatpak, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432\u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f | ProHoster","og:description":"\u0412 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u043e\u0432 \u043d\u0430\u0437\u0430\u0434 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0441\u0430\u043c\u043e\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 Flatpak 1.16.4, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430\u043b\u044c\u043d\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 1.17.4, \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-34078), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-vo-flatpak-pozvolyayushhaya-vypolnit-kod-vne-izolirovannogo-okruzheniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-08T09:11:59+00:00","article:modified_time":"2026-04-08T09:11:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/167905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=167905"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/167905\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=167905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=167905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=167905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}